7.8
CVSSv3

CVE-2017-13209

Published: 12/01/2018 Updated: 24/08/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217907.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 8.1

google android 8.0

Exploits

This bug is similar to Jann Horn's issue (bugschromiumorg/p/project-zero/issues/detail?id=851) -- credit should go to him The hardware service manager allows the registration of HAL services These services are used by the vendor domain and other core processes, including system_server, surfaceflinger and hwservicemanager Similarly to ...